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SUBJECT: Interagency Group/Countermeasures ~ Tasking 
on National Policy on Damage Assessments 


1. Pursuant to Interagency Group/Countermeasures tasking, 
the Unauthorized Disclosures Investigations Subcommittee (UDIS) 
of the DCI Security Committee, at my request, prepared a report 
entitled "Points for Consideration Relative to a National Policy 
on Damage Assessments." The report was reviewed and unanimously 
agreed to by all of the UDIS members who attended the 8 October 1982 
UDIS meeting (Air Force, Army, CIA, DIA, Energy, FBI, SAFSS, 
Treasury and Navy). A copy of the UDIS report is forwarded 
herewith for your reference. 


2. The UDIS members have now formally responded in writing 
to the Chairman of the Security Committee, setting out in detail 
their organizations' positions with respect to the establishment 
of a national policy on damage assessments. A copy of those 
comments is also forwarded herewith. 


3. In essence, there is agreement among the UDIS members 
that Information Security Oversight Office (1800) Directive No. 1 
(32 CFR Part 2001) provides appropriate policy on damage 
assessments and that agency heads should be responsible for 
handling their own damage assessments. There is also a consensus 
favoring some sort of sharing of lessons learned from damage 
assessments. 


4. It was suggested that a selective sharing of damage 
assessment information through means of a newsletter such as the 
Air Force now publishes might be appropriate. Air Force, Army, 
Justice, Navy and the Office of the Secretary of Defense (OSD) 
provided supporting comments in this regard. The OSD 
specifically recommended that the Security Awareness Subcommittee 
of the SECOM be charged to examine the value of sharing damage 
assessment data from a lessons-learned perspective. 
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5. Judicious sharing within the Intelligence Community of 
data learned from damage assessments seems to me reasonable 
enough, provided that the data base itself does not become a 
source for “leakers." To share the information effectively we 
must, I believe, first determine what data elements would be 
included, how the information would be controlled, and who would 
absorb the associated costs both in dollars and manpower. 


6. I recommend, therefore, that the Unauthorized 
Disclosures Investigations Subcommittee of SECOM be tasked to 
prepare a plan of action on sharing damage assessment information 
among appropriate agencies of the Federal Government. When and 
if agreement is reached on an appropriate mechanism for such 
sharing, I would suggest that the DCI Security Committee be 


designated the central repository of the information thus 


obtained. 
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